7.5
CVSSv3

CVE-2021-37189

Published: 10/12/2021 Updated: 14/12/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists on Digi TransPort Gateway devices up to and including 5.2.13.4. They do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in cleartext over an HTTP session.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

digi transport_wr11_firmware

digi transport_wr11_xt_firmware

digi transport_wr21_firmware

digi transport_wr31_firmware

digi transport_wr41_firmware

digi transport_wr44_firmware